Secure Peripheral Device Booting Secondary Operating System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage devices, such as USB flash drives, lack security, making it risky to store and boot operating systems from them, especially when lost or stolen, as they do not provide adequate protection for confidential data.
Innovation Solution
A secure peripheral device is developed that includes a memory with a device secure channel engine, cryptography module, challenge generation module, and verification module, allowing secure communication with a host computer and enabling the booting of a secondary operating system from a secure, encrypted area, using cryptographic technologies like AES and RSA to ensure data integrity and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If operating systems are stored on USB flash drives for portability and energy efficiency, then device portability and energy consumption are improved, but security protection is worsened
Solution Approach 1:
The patent segments the USB flash drive into distinct functional modules: a secure element containing cryptographic keys and a file system area for storing operating systems. This segmentation isolates security-critical components from general storage functions, allowing the system to maintain portability while protecting sensitive data through physical and logical separation of security functions from storage functions.
Solution Approach 2:
The patent introduces a secure element as an intermediary component between the host computer and the stored operating systems. This secure element acts as a mediator that verifies bootloaders and operating systems before execution, providing security protection without compromising the portability benefits of USB-based booting.
2Reliability
If cryptographic security measures are implemented in peripheral devices, then security protection is improved, but device complexity is worsened
Solution Approach 1:
The patent extracts complex cryptographic functions from the main processor and places them in a dedicated secure element. This extraction isolates security-critical operations in a separate, specialized component, reducing the complexity burden on the main system while maintaining strong security protection through hardware-based cryptography.
Solution Approach 2:
The secure element provides self-service cryptographic operations, independently verifying bootloaders and operating systems without requiring complex security management from the host system. This self-service capability simplifies the overall system architecture by making security autonomous and reducing inter-component complexity.
Data Source
AI summary
An operating system is booted from a secure peripheral device on a host computer. The secure peripheral device, which includes a memory, is communicatively coupled with the with the host computer. A first operating system is booted from the memory of the secure peripheral device. A secondary operating system is launched on the first operating system.


